import re, time
import os
import urllib.parse, urllib.request
from subprocess import *

# mode=Popen('tshark -r  *.pcap -T fields -e http.file_data -Y "http.request.method==POST"  > res.txt',shell=True,stdout=PIPE,stderr=STDOUT,encoding="utf-8")
# print(mode.stdout.read().strip())

# os.popen('tshark -r  *.pcap -T fields -e http.file_data -Y "http.request.method==POST"  > res.txt')
# time.sleep(5)
# print()

with open('sql', 'r', encoding='UTF-8') as f:
    lines = f.readlines()

lines = [urllib.parse.unquote(line.strip()) for line in lines]

dics = {}
list1 = []
for i, line in enumerate(lines):
    if 'sleep(3))' in line:
        c = re.search(r'01/Mar/(.+?) -0500', line).group(1)
        a = re.search(r"limit 0,1\),(.+?),1\)=binary", line).group(1)
        b = re.search(r"binary\('(.+?)'\),1,sleep", line).group(1)
        # dics[a]=chr(int(b))
        # print(c,b,a)
        list1.append((c, b, a))
print(list1)
# print(dics)
# print(''.join([dics[i] for i in dics]))
for i in range(1, len(list1)):
    tmp = int(list1[i][0].split(':')[-1]) - int(list1[i - 1][0].split(':')[-1])
    if tmp == 0:
        dics[list1[i - 1][2]] = list1[i - 1][1]
print(''.join([v for k, v in dics.items()]))